Information security consultant
You will join an organization where your interest in cybersecurity and management consulting converge. This organization believes in the positive power of technology and the value of teamwork. Since 2014, they have been working with a team of over 60 cybersecurity experts towards a common goal: enabling organizations to operate safely and successfully in the digital world. They stand for maximum impact and maximum growth - not only for their clients, but also for their employees.
In everything they do, they combine a winning mentality with integrity and quality. Together, they create solutions that work not only today, but also for the future.
What you will do. You will be part of a dedicated security team of approximately 20 employees who are already enthusiastically working on various security projects in different sectors. As an Information Security Officer, you will be the one who:
- Establishes risk management frameworks, identifies risks, and prioritizes them within the risk treatment plan.
- Provides updated action plans to elevate other companies to a higher security level.
- Implements and manages Information Security Management Systems (ISMS).
- Defines technical and process security measures in documented policies, processes, and standards.
- Helps organizations obtain a security certificate.
- Conducts security and privacy compliance assessments according to specified requirements of a security and privacy framework.
- Quickly identifies shortcomings and reports them immediately to the client.
- Translates shortcomings into concrete measures to meet requirements.
- Helps the organization comply with legal standards.
Profile
You are a social person who thrives on giving advice and supporting others.
- You adapt easily to different situations.
- You motivate those around you and offer valuable insights, always with respect and empathy.
- You take responsibility for your actions and consistently act with integrity.
- Your discretion and self-discipline are reflected in the quality of your work.
- Your expertise stands out in your projects.
- You are dedicated to expanding your knowledge and equally enthusiastic about sharing it with others.
What they ask
- Relevant Bachelor's or Master's degree in economics, IT, or an equivalent (engineering, sciences, computer science, statistics).
- Knowledge of security risk management methodologies such as: ISO27005, ISO31000, and COSO.
- Performing security risk analyses, business impact assessments, and control assessments.
- Ability to implement and manage an Information Security Management System (ISMS).
- Knowledge of security and privacy standards and governance frameworks such as ISO27001/2, ISO27701, NIST CSF, CIS Controls, CyberFundamentals.
- Knowledge of relevant laws and regulations such as NIS2, DORA, CRA, GDPR.
- Performing an audit and preparing an assessment plan (in accordance with ISO190011).
- Validating control measures and reporting assessment results.
- Ability to provide professional advice in Dutch and English.
Preferences.
- One of the following certificates: ISO27001 Lead Implementer, ISO27001 Lead Auditor, Certified DPO, CISM, CISSP, and CISA.
- A technical background to make a good translation to the business.
- Experience in one of the following areas:
- Identity, Access, Vulnerability, and Patch Management
- Security in the software lifecycle
- Cloud security (EMS o365, MS Azure, AWS)
- Network technology: Routing and switching standards, VPN
- Experience in security domains and standards
- Cryptography (incl. Key Life Cycle Management) and Public Key Infrastructure.
- French is a plus.
How to apply
View the full assignment text and application details once your tailored application is ready.
Order a tailored application to view the full assignment and application details.
More context, less searching.
You get enough context to judge whether this job is relevant. The full brief, client details and next steps stay available inside the app.